Has anyone used the gsuite app for splunk developed by Kyle Smith to track deleted emails?
I'm wondering if someone had a working query they could share?
How exactly would that work? What is the log source you are trying to use? Is there a feature you are looking for? join us on slack (splk.it/slack) in #gsuite_app to discuss